Cryptonews Core Lightning Fixes Critical Flaw in Channel Management
Article Content
- •A flaw in Core Lightning allowed old channel states to be broadcast without penalties.
- •Operators must update to at least v26.06.8 to mitigate the risk.
- •Docker users need to verify image digests to ensure they have the correct version.
Core Lightning has patched a significant flaw in its v26.06.7 release that allowed a peer to broadcast an old, revoked channel state without incurring penalties for cheating. This vulnerability could be exploited if a peer did not specify an upfront shutdown script when opening a channel, enabling them to present a revoked commitment as legitimate. The fix, detailed in Bitcoin Optech's report from September 25, 2026, checks transaction locktime and sequence encoding to prevent such exploits. Operators using versions older than v26.06.7 are urged to update to v26.06.8, which includes additional security fixes. Docker users must verify their image digests due to a previous issue where the images reported the new version but lacked the necessary fixes. The vulnerability is specific to Core Lightning's channel management and does not affect Bitcoin's base-chain rules.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Core Lightning in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…