Operators using version 26.06.7 or earlier are urged to update immediately
Core Lightning urged operators using version 26.06.7 or earlier to update to the latest release, after receiving reports that attackers may be targeting outdated nodes. The team did not specify which vulnerabilities might be involved or their potential impact.
On September 16, Core Lightning said it was investigating a possible issue in experimental features that could have affected user funds. About six days later, it released version 26.06.8, with bug fixes and patches for vulnerabilities responsibly reported by multiple sources.
According to the changelog, some fixes address flaws that could cause sending nodes to crash, requests capable of exhausting memory in the REST interface, and a channel-closing bug that could cause users to lose funds through a penalty. The project withheld some tests to make it harder to reconstruct and exploit the vulnerabilities during updates.
In August, Core Lightning said it was working on a coordinated fix after assessing a large number of AI-generated CVE reports. Two days later, it released version 26.06.7 to address confirmed vulnerabilities.





