Core Lightning (CLN), a widely used implementation of the Bitcoin Lightning Network, has published a CVE vulnerability report and is urging all node operators to take their nodes offline immediately. The advisory, first reported by Crypto Briefing, does not disclose technical details of the flaw, citing a two-week embargo intended to give operators time to apply patches.
According to the report, all nodes running CLN version 26.04 or earlier are affected. Support for those versions has officially ended, and a patched version has not yet been released. The Core Lightning team recommended that operators either update with signed binaries when available or restart their node daemon using the --offline flag. The latest stable release tagged in the project's official GitHub repository is v26.06.6, published on July 22, 2026, but it does not contain the fix.
The warning gained wider visibility after Calle, developer of the Cashu protocol, publicly urged the community to disconnect nodes. Mark Erhardt, Bitcoin Core contributor and researcher at Localhost Research, independently confirmed that the request originated from the official maintainers of the Blockstream-developed implementation.
The CLN team stated that the bug review began after receiving multiple vulnerability reports generated by artificial intelligence tools throughout August 2026. They noted that like many Bitcoin open-source projects, CLN had received a flurry of AI-generated CVE reports and that the team had been working to validate, triage, and develop fixes where appropriate. Data from the volunteer initiative Bitcoin Red Team indicates that recent automated scans generated 4,962 security findings across 390 ecosystem repositories, including 85 flaws classified as critical and 635 of high severity.
This incident marks the fourth security advisory involving Bitcoin infrastructure within a 30-day window. In late July 2026, a firmware flaw in Coldcard hardware wallets facilitated the theft of approximately $114 million in BTC, followed by independent technical notices affecting the Boltz and BTCPay Server protocols. Core Lightning version 26.09 remains scheduled for late September 2026, but operators are advised not to wait for that broader release and to apply the security patch as soon as it is published.