← Back to news

September 26, 2026

Core Lightning ships 26.06.8, urges immediate upgrade over reported vulnerabilities

Core Lightning, one of the most widely run node implementations for Bitcoin's Lightning Network, pushed out version 26.06.8 on September 22. According to Freedom.Tech, the release bundles routine bug fixes together with patches for "vulnerabilities responsibly reported by a number of sources" — meaning outside researchers found and privately disclosed the issues before this release shipped.

What stands out is the disclosure approach. Unlike the prior 26.06.7 release, which followed a coordinated embargo period, the maintainers say there was no embargo this time: the fixes went out the moment they were ready. To slow down anyone trying to reverse-engineer the vulnerabilities from the code changes, the team also withheld a small number of tests that would otherwise make the underlying bugs easier to identify.

"We strongly recommend upgrading to this release."

The advisory doesn't publish CVE numbers or a technical breakdown of each flaw — a deliberate choice, since publishing exploit details before most operators have upgraded would hand attackers a head start. Node runners are told to treat the upgrade as a priority rather than routine maintenance.

A few practical notes for anyone running a Core Lightning node: dual funding remains an experimental feature, zero-confidence channels with peers you don't already trust are discouraged, and nodes running development builds cannot downgrade back to a 26.06.x release because of database schema changes made along the way.

Lightning Network security work rarely makes headlines the way exchange hacks do, but node-level bugs are exactly the kind of thing that can put self-custodied funds at risk before most users ever hear about it. If you or someone you rely on runs a Lightning node, checking that it's current with 26.06.8 is worth doing today rather than waiting for the next reminder.

— WalletRecover Team

Source: Freedom.Tech