Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.
Source: NVD ↗ · CISA KEV Catalog ↗