Core Lightning, an open-source implementation of the Bitcoin Lightning Network, confirmed multiple real vulnerabilities on Aug 27, 2026. The confirmation came amid a high volume of AI-generated CVE reports. The project urged node operators to install a forthcoming security update. Until that update ships, operators can run the node with the --offline flag, which stops payments from entering, leaving, or routing through it. Severity and technical details have not been disclosed, and no CVE identifiers have been published. No exploitation or losses are reported as of this writing. The confirmed flaws are separate from the remote denial-of-service vulnerabilities the project addressed in May and July 2026. Coverage from CoinDesk, Cointelegraph, and Decrypt corroborates the advisory.
Core Lightning project advisory; CoinDesk, Cointelegraph, Decrypt