An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
https://support.zabbix.com/browse/ZBX-23857
https://lists.debian.org/debian-lts-announce/2024/10/msg00000.html