Core Lightning, the Bitcoin Lightning Network implementation maintained by Blockstream, ordered node operators on August 26 to disconnect immediately due to unpatched critical vulnerabilities. All versions 26.04 and earlier are affected, and no patched version is available yet, leaving operators unable to upgrade. The disclosure reportedly came after AI-generated CVE reports helped uncover exploitable security flaws. Start9 released update version 26.6.6 which automatically takes nodes offline to protect on-chain funds and channel states. On the same day, LND, the competing Lightning implementation developed by Lightning Labs, also faced a vulnerability disclosure affecting versions prior to 0.21.0.
Source: Read the original article

