Bitbo Core Lightning Urges Node Operators Offline Due to Vulnerabilities
Article Content
- •Core Lightning advises immediate offline operation for nodes running version 26.04 or earlier.
- •A patch is expected within 48 hours, but technical details are under a two-week embargo.
- •No confirmed exploitation has been reported, but the vulnerabilities pose a high risk to funds.
Core Lightning has disclosed multiple vulnerabilities affecting all nodes running version 26.04 or earlier, urging operators to take their nodes offline immediately. The vulnerabilities were identified through AI-generated CVE reports, and while a patch is expected within 48 hours, a two-week embargo on technical details is in place. Operators are advised to use the --offline mode to keep their nodes active without routing transactions, as stopping the node entirely would prevent monitoring of the Bitcoin blockchain. No confirmed exploitation has been reported, but the urgency of the advisory suggests a significant risk of fund loss and network disruption. The incident highlights ongoing challenges in maintaining secure decentralized infrastructure, particularly as public channel capacity on the Lightning Network has declined significantly over the past months.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Core Lightning and CVE-2024-52911 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Core Lightning Urges Immediate Upgrade Amid Targeted Attacks on Outdated Nodes Core Lightning developers issued an urgent warning on October 2, 2026, advising operators of Bitcoin Lightning Network nodes running version 26.06.7 or earlier to upgrade immediately due to active targeting by attackers. The vulnerabilities being exploited have not been disclosed, and no confirmed theft of funds has…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…