Which means that the attack surface for OpenBSD is just their TCP/IP stack and SSH. The slogan, while technically correct, sounds like (and dare I say, is often taken as) saying that there have been no security bugs/network RCE bugs in OpenBSD. OpenBSD has shipped with many RCE vulnerabilities over the years (in its included FTP and HTTP servers, for example). Simply in services not enabled by default. Because none of them are enabled by default.
I'm not particularly impressed by OpenBSD in this particular regard because if you want to do something with your computer, you will eventually end up needing to enable services, some of which have had bugs shipped with OpenBSD. And once you install 3rd party software, all bets are off.
One thing OpenBSD has focused on recently I am a huge fan of is their documentation and focus on making consistent and easy to read and write config files. That is a huge bonus to security IMO. Making it easier to learn how and to write configs makes the chances of misconfiguring a server much lower, which is more often the bigger security risk.