CVE-2026-20963 CrowdStrike LogScale · LogScale

Detect Microsoft SharePoint Deserialization of Untrusted Data (CVE-2026-20963) in CrowdStrike LogScale

Detects exploitation of CVE-2026-20963, a deserialization of untrusted data vulnerability in Microsoft SharePoint. Attackers can send crafted serialized payloads to SharePoint endpoints, leading to remote code execution in the context of the SharePoint application pool. This CVE is listed on the CISA KEV catalog, indicating active exploitation in the wild.

MITRE ATT&CK

Tactic
Initial Access Execution Persistence

LogScale Detection Query

CrowdStrike LogScale (LogScale)
cql
event_type=ProcessRollup2
| filter ParentBaseFileName="w3wp.exe"
  AND FileName IN ("powershell.exe", "cmd.exe", "wscript.exe", "cscript.exe", "mshta.exe", "certutil.exe", "bitsadmin.exe", "regsvr32.exe")
| eval RiskReason=case(
    FileName="powershell.exe", "PowerShell spawned by SharePoint IIS worker",
    FileName="certutil.exe", "certutil spawned by IIS worker - potential payload staging",
    FileName="mshta.exe", "mshta spawned by IIS worker - script execution risk",
    true(), "Suspicious binary spawned by w3wp.exe"
  )
| table timestamp, ComputerName, UserName, ParentBaseFileName, FileName, CommandLine, RiskReason
| sort -timestamp
critical severity high confidence

CrowdStrike Falcon query detecting w3wp.exe (SharePoint IIS worker) spawning commonly-abused living-off-the-land binaries, indicating post-exploitation from deserialization.

Data Sources

CrowdStrike Falcon Endpoint Protection

Required Tables

ProcessRollup2

False Positives & Tuning

  • SharePoint automation runbooks invoking PowerShell from IIS context
  • Custom workflow activities that shell out to cmd.exe for legacy processing
  • Endpoint agents initiating remediation scripts via IIS worker

Other platforms for CVE-2026-20963


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Simulate SharePoint Deserialization Child Process Spawn

    Expected signal: Process creation event (Event ID 4688 or Sysmon Event ID 1) with ParentImage matching w3wp_sim.exe and Image matching powershell.exe

  2. Test 2Craft and Submit Malformed Serialized Payload to SharePoint Endpoint

    Expected signal: IIS access log entry showing POST to /_api/web/lists with non-JSON content-type or anomalous body size; WAF or SIEM alert on malformed serialized content

  3. Test 3Simulate Credential Dumping Post-Exploitation via w3wp.exe Context

    Expected signal: Process creation event showing cmd.exe or tasklist.exe executed under SharePoint application pool identity; Event ID 4656/4663 if LSASS handle access is attempted

Unlock Pro Content

Get the full detection package for CVE-2026-20963 including response playbook, investigation guide, and atomic red team tests.

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections