Core Lightning released emergency patch 26.06.7 to address an exploit; source code delayed two weeks to prevent abuse.
Security & Exploits ·
Core Lightning released an emergency patch, version 26.06.7, and urged operators to upgrade in response to a vulnerability in the software. To mitigate the risk of exploitation before users could secure their systems, the project delayed public release of the source code by two weeks.
The delayed disclosure approach is a common practice in security responses, allowing time for the installed base to patch before detailed technical information becomes available to potential attackers. In this case, the two-week window was intended to provide a window for operators running Core Lightning nodes to apply the fix before the underlying vulnerability could be widely understood or weaponized.
What remains unclear is the scope and severity of the vulnerability itself—whether it posed an immediate threat to funds, network stability, or specific operations, and whether any active exploitation occurred before the patch was released. The rationale for the specific two-week delay and the technical nature of the flaw have not been detailed in available announcements.