Core Lightning (CLN) released v26.06.7 on August 28, 2026 as a security point release. It bundles fixes for vulnerabilities reported by a number of researchers.
The project says increasingly capable AI models are now being used to find potential flaws in open-source code, raising the volume and pace of security reports. The credit list mixes human researchers with at least one AI-linked account, a shift from the usual disclosure roster.
The fix source code is under a two-week embargo. It will be published 14 days after release. The delay is meant to slow attackers who might reverse-engineer the patches and exploit the network before it updates.
Docker operators faced an extra wrinkle. Between August 28 16:04 UTC and September 1, image tags served placeholder builds that reported v26.06.7 on startup but did not contain the fixes. Those manifests were replaced. Users were told to check the image digest and re-pull if it does not match.
Operators pinned to v26.06.6 or earlier were never affected.
The episode shows how AI-assisted auditing changes the disclosure cycle for open-source infrastructure: more reports reach maintainers faster, and the window between announcement and source publication becomes a deliberate security step.
Core Lightning official release notes