Statistics: Reported vulnerabilities
CVE: Number of published vulnerabilities
The NCSC is the official contact point for reporting security vulnerabilities in Switzerland and maintains their CVE IDs for international exchange. In this role, the NCSC is responsible for preparing and publishing information about the vulnerabilities reported to it and the associated CVE records.
2026
2025
Further information on vulnerabilities (Coordinated Vulnerability Disclosure, CVD):
Vulnerabilities (Coordinated Vulnerability Disclosure, CVD)
Bug bounty programme: Number of reported vulnerabilities
In order to increase its cyber security and reduce cyber risks effectively and cost-efficiently, the Federal Administration runs bug bounty programmes under the leadership of the NCSC and in cooperation with other administrative units and Bug Bounty Switzerland AG.
Further information on the bug bounty programme:
Bug bounty programme to increase cyber-resilience in the Federal Administration


