# Core Lightning Announces v26.06.9 With Security and Payment Fixes

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/28737
Published: 2026-10-09T05:26:00.000Z
Updated: 2026-10-09T05:26:00.000Z
Section: Technology

> The update addresses vulnerabilities, a CPU-budget regression affecting busy nodes and an HTLC shutdown issue that could put forwarded funds at risk.

Core Lightning announced v26.06.9 on Oct. 7 at 9:19 a.m. ET (13:19 UTC), combining multiple security fixes with repairs to a performance regression and an issue involving forwarded payments on the Bitcoin Lightning Network.

The update addresses vulnerabilities involving channel reestablishment, splicing, hashed timelock contracts (HTLCs), onion handling, on-chain dispute resolution, gossip range queries, runes and the setconfig method. The announcement came Oct. 7, while the changelog dates the software release to Oct. 6.

Core Lightning is open-source software used to operate nodes on the Lightning Network, which enables Bitcoin (BTC) payments through interconnected payment channels. The project recommends that all users upgrade to v26.06.9.

The update also corrects a CPU-budget problem introduced in v26.06.8. Ordinary gossip, ping and onion messages could consume capacity reserved for gossip range queries, potentially throttling peers and delaying channel traffic on busy nodes. The new version limits that budget to gossip range queries.

A separate fix applies when a channel begins closing before an outbound conditional payment expires. Core Lightning now force-closes the channel in that situation, preventing forwarded funds from being lost if the payment is fulfilled late, after the deadline and during the shutdown process.

The release changes rune controls as well. Restricted runes can no longer create unrestricted runes or relist blacklisted runes, and the invokerune and destroyrune aliases now face the same checks as their corresponding methods.

The listconfigs command now masks sensitive values in the wallet, recover, tor-service-password, bitcoin-rpcpassword and legacy bookkeeper-db fields for every caller.

Tests for the security fixes are temporarily withheld to give node operators more time to upgrade and reduce the risk that the fixes could quickly be turned into working exploits. The release lists no CVE numbers, severity ratings or evidence of exploitation.

The update follows [Core Lightning’s warning about attackers targeting unpatched nodes](<https://www.tokenpost.com/news/technology/26403>). It includes signed reproducible arm64 and armv7 binaries for Ubuntu 22.04, 24.04 and 26.04.

## Links in this article

- [Core Lightning’s warning about attackers targeting unpatched nodes](https://www.tokenpost.com/news/technology/26403)
